Blog · Governance

Governance is not an enterprise add-on.
At Canvos it is on by default.

How we enforce sharing policy, DLP, retention and legal hold across Canvos, Nextcloud and Euro Office, how Nextcloud approaches it with its new Governance app, and why you do not need a hundred users to get it from us.

Canvos · Product8 min readGovernance · Compliance · Nextcloud

A three-person law firm keeps files as sensitive as a bank with three thousand staff. An accountant with one employee e-mails national registry numbers as often as a hospital does. The GDPR does not care about headcount, and NIS2 looks at the sector, not at the number of desks. Yet almost every vendor sells governance as something for the big customer: a separate licence, an enterprise tier, a minimum number of users.

We think that is upside down. Policy that enforces itself is exactly what a small organisation needs, because nobody there has time to check it by hand. That is why the Governance Center is part of every Canvos plan, from a single user upwards, without an extra module.

Whoever is too small for a compliance department benefits most from software that does the work.

What it isOne screen, ten tabs, no exceptions

The Governance Center is the one place where an administrator sets the organisation's policy. Not as a document in a folder, but as rules the platform carries out:

Where it countsEnforced, not just stored

A setting that only lives in a database is an intention. Governance begins when the rule also applies to people who never saw the setting. That is why Canvos enforces every policy at four points at once:

1 · CanvosEvery action in the workspaceSharing, chat shares, uploads, downloads and e-mail all pass through the policy. A blocked action gets a clear reason, not a silent failure.
2 · NextcloudThe underlying storageLinks, password requirement, expiry, group sharing, federation, trash and versions are set in Nextcloud itself. The desktop client and WebDAV do not bypass them.
3 · Euro OfficeDocuments in the editorThe watermark from the sharing policy appears in Euro Office, our European office suite, and on pdf downloads. With the user's name and the time.
4 · MobileThe app on the phoneScreen protection against screenshots and recordings, driven by the same policy.

An example. An employee uploads an export of the staff list to a shared folder. The file is called list.xlsx, harmless enough. The content DLP rule reads the sheet, finds two valid national registry numbers and blocks the upload. The employee sees why. The administrator gets a notification. And it is recorded in the log, with a hash that can no longer be changed.

Events · example.comhash chain · last 6 of 1,284
ChainActionWhatResult
#1284 e7c1…9auploadlist.xlsx
national registry number (2x)
Blocked
#1283 41f0…2dsharequote-2026-118.pdf
external, awaiting administrator
Approval
#1282 c88a…70downloadlease-contract.pdf
Confidential, watermarked
Allowed
#1281 0d5e…b3legal-holdcase-2024-031/
legal hold: ongoing proceedings
Set
#1280 9b12…f4emailto competitor.example
blocked domain
Blocked
#1279 77ae…c0retentionchat older than 365 d
21 rooms cleaned up
Done
Chain intact · 1,284 events · today's anchor signedexport: CSV · JSON · CEF

EvidenceA log you cannot alter, and neither can we

Every event gets a sequence number and a sha256 hash over its content plus the hash of the previous line. Whoever changes or deletes a single line breaks the chain from that point on, and you see it with one click. Every day the platform signs the latest point of the chain with a key that exists for that purpose only. An auditor can recompute it without taking our word for it.

The same facts feed the compliance report. Not a questionnaire someone fills in, but a pdf, csv or xlsx with what actually happened: how many actions, how many blocked, which rules intervened most, whether the chain is intact, and which policy was in force. The monthly report lands in the mailbox of whoever you name.

Compliance score · example.comcomputed from facts, not from a questionnaire
86of 100
  • Classification active and enforced10 / 10
  • DLP rules on content10 / 10
  • Public links: password and expiry10 / 10
  • Event chain intact10 / 10
  • Nextcloud synchronised10 / 10
  • Retention configured and running10 / 10
  • Mobile: screen protection0 / 5
  • Alerts or monthly report configured0 / 5

For comparisonHow Nextcloud does it

Canvos is built on Nextcloud, so we follow closely what Nextcloud itself does here. In August 2026 a preview of Nextcloud Governance appeared: sensitivity labels, retention policies, legal hold, DLP and a Compliance Manager with a score. Eric Burger wrote a thorough, honest review of it (in Dutch), and it is worth reading.

Nextcloud's strongest point is that it sits in the core: the rules apply to every client. Legal hold really does block editing and deletion. That is also why we push our sharing policy and retention into that same core instead of only building on top of it.

The review is just as clear about what is not there yet. Retention did not work on Nextcloud 34 in the tested version. Labels are applied by hand. A document under retention remains editable. There is no retention at team-folder level and no disposition list with approval. And the point that matters most to anyone reading this: Nextcloud Governance is an Enterprise feature, not in the App Store, with a minimum of one hundred users.

AreaCanvos Governance CenterNextcloud Governance (preview)
Available toevery plan, from one user, includedEnterprise, from one hundred users
Scopefiles, e-mail, chat, mobilefiles
EnforcementCanvos, Nextcloud, Euro Office, mobile appin the Nextcloud core, for all clients
DLPname, type, size, domain, and content with national registry number, IBAN, card number, custom regexpresent, not described in detail in the review
Retentionper organisation, run by a worker, with a dry run firstper document, two actions; not yet working on NC34 in the tested version
Legal holdper file, with reason, blocked in Canvos and locked in Nextcloudworks, blocks editing and deletion; sits with the user rather than with a role
Approvalexternal shares and DLP hits through a request to the administratornot described
Loghash chain, signed daily, export CSV, JSON, CEFnot described
Report and scorescore on facts, report pdf, csv, xlsx, monthly by e-mailCompliance Manager with score, details unknown

Nextcloud column based on the review of preview 1.0.1 (August 2026). Nextcloud has announced improvements for coming releases.

Honest about the limits. Nextcloud has no legal hold an administrator can place on someone else's personal files. For files in team folders Canvos locks the file for everyone. For a personal file Nextcloud locks it in the owner's name: every other user is then blocked over WebDAV as well, the owner within Canvos. That is stated on screen, not in the small print.

The choiceDefault, from one user

We could have put governance in a separate tier. That is what the market is used to, and it is an easy way to raise a price tag. We do not, for a simple reason: the organisations at the greatest risk are precisely the ones that will never buy an enterprise licence. A notary, a GP practice, an architecture firm. They have no compliance officer. They need a platform that knows the rules.

Concretely. Every Canvos plan includes the full Governance Center: sharing policy, e-mail policy, retention, classification, DLP on content, approvals, legal hold, mobile policy, compliance score, reports and the chained log. For one user or for a thousand. No module, no surcharge.

Governance is not a luxury for the large. It is the baseline for anyone who handles other people's data seriously. With us that baseline simply comes included.

See the Governance Center in a demo

Twenty minutes, your own scenario. We set up a content DLP rule, a legal hold and an approval flow live, and show what the log holds afterwards.

Book a demo

Examples with example.com are illustrative.